9.8
    Critical

    CVE-2018-12327

    Last Modified: 20 Jun 2018

    Stack-based buffer overflow in ntpq and ntpdc of NTP version 4.2.8p11 allows an attacker to achieve code execution or escalate to higher privileges via a long string as the argument for an IPv4 or IPv6 command-line parameter. NOTE: It is unclear whether there are any common situations in which ntpq or ntpdc is used with a command line from an untrusted source.

    Source:Fakhri Zulkifli
    Published:20 Jun 2018
    8.4
    High

    CVE-2018-12326

    Last Modified: 19 Jun 2018

    Buffer overflow in redis-cli of Redis before 4.0.10 and 5.x before 5.0 RC3 allows an attacker to achieve code execution and escalate to higher privileges via a crafted command line. NOTE: It is unclear whether there are any common situations in which redis-cli is used with, for example, a -h (aka hostname) argument from an untrusted source.

    Source:Fakhri Zulkifli
    Published:13 Jun 2018
    8.8
    High

    CVE-2018-12293

    Last Modified: 17 Aug 2018

    The getImageData function in the ImageBufferCairo class in WebCore/platform/graphics/cairo/ImageBufferCairo.cpp in WebKit, as used in WebKitGTK+ prior to version 2.20.3 and WPE WebKit prior to version 2.20.1, is vulnerable to a heap-based buffer overflow triggered by an integer overflow, which could be abused by crafted HTML content.

    Source:PeregrineX
    Published:19 Jun 2018
    9.8
    Critical

    CVE-2018-12292

    Last Modified: 19 Jun 2018

    A use-after-free vulnerability exists in DOMProxyHandler::EnsureExpandoObject in Pale Moon before 27.9.3.

    Source:Berk Cem Göksel
    Published:13 Jun 2018
    8.8
    High

    CVE-2018-12254

    Last Modified: 19 Jun 2018

    router.php in the Harmis Ek rishta (aka ek-rishta) 2.10 component for Joomla! allows SQL Injection via the PATH_INFO to a home/requested_user/Sent%20interest/ URI.

    Source:Guilherme Assmann
    Published:12 Jun 2018
    6.1
    Medium

    CVE-2018-12234

    Last Modified: 12 Nov 2019

    A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Adrenalin 5.4.0 HRMS Software. The user supplied input containing JavaScript is echoed back in JavaScript code in an HTML response via the flexiportal/GeneralInfo.aspx strAction parameter.

    Source:Cy83rl0gger
    Published:6 Sept 2018
    8.8
    High

    CVE-2018-12114

    Last Modified: 15 Jun 2018

    Maccms 10 allows CSRF via admin.php/admin/admin/info.html to add user accounts.

    Source:bay0net
    Published:14 Jun 2018
    6.1
    Medium

    CVE-2018-12111

    Last Modified: 12 Jun 2018

    Cross-site scripting (XSS) vulnerability in the Canon PrintMe EFI webinterface allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the /wt3/mydocs.php URI.

    Source:Huy Kha
    Published:11 Jun 2018
    5.4
    Medium

    CVE-2018-12095

    Last Modified: 19 Jun 2018

    A Reflected Cross-Site Scripting web vulnerability has been discovered in the OEcms v3.1 web-application. The vulnerability is located in the mod parameter of info.php.

    Source:Renzi
    Published:11 Jun 2018
    5.4
    Medium

    CVE-2018-12094

    Last Modified: 19 Jun 2018

    Cross-site scripting (XSS) vulnerability in news.php in Dimofinf CMS Version 3.0.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter.

    Source:Renzi
    Published:11 Jun 2018
    6.1
    Medium

    CVE-2018-12090

    Last Modified: 8 Aug 2018

    There is unauthenticated reflected cross-site scripting (XSS) in LAMS before 3.1 that allows a remote attacker to introduce arbitrary JavaScript via manipulation of an unsanitized GET parameter during a forgotPasswordChange.jsp?key= password change.

    Source:Nikola Kojic
    Published:11 Jun 2018
    7.5
    High

    CVE-2018-12086

    Last Modified: 21 Nov 2024

    Buffer overflow in OPC UA applications allows remote attackers to trigger a stack overflow with carefully structured requests.

    Published:14 Sept 2018
    9.8
    Critical

    CVE-2018-12055

    Last Modified: 11 Jun 2018

    Multiple SQL Injections exist in PHP Scripts Mall Schools Alert Management Script via crafted POST data in contact_us.php, faq.php, about.php, photo_gallery.php, privacy.php, and so on.

    Source:M3@Pandas
    Published:8 Jun 2018
    7.5
    High

    CVE-2018-12054

    Last Modified: 11 Jun 2018

    Arbitrary File Read exists in PHP Scripts Mall Schools Alert Management Script via the f parameter in img.php, aka absolute path traversal.

    Source:M3@Pandas
    Published:8 Jun 2018
    7.5
    High

    CVE-2018-12053

    Last Modified: 11 Jun 2018

    Arbitrary File Deletion exists in PHP Scripts Mall Schools Alert Management Script via the img parameter in delete_img.php by using directory traversal.

    Source:M3@Pandas
    Published:8 Jun 2018
    9.8
    Critical

    CVE-2018-12052

    Last Modified: 11 Jun 2018

    SQL Injection exists in PHP Scripts Mall Schools Alert Management Script via the q Parameter in get_sec.php.

    Source:M3@Pandas
    Published:8 Jun 2018
    4.2
    Medium

    CVE-2018-12038

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung 840 EVO devices. Vendor-specific commands may allow access to the disk-encryption key.

    Published:20 Nov 2018
    7.8
    High

    CVE-2018-12036

    Last Modified: 21 Nov 2024

    OWASP Dependency-Check before 3.2.0 allows attackers to write to arbitrary files via a crafted archive that holds directory traversal filenames.

    Published:7 Jun 2018
    9.8
    Critical

    CVE-2018-12031

    Last Modified: 21 Nov 2024

    Local file inclusion in Eaton Intelligent Power Manager v1.6 allows an attacker to include a file via server/node_upgrade_srv.js directory traversal with the firmware parameter in a downloadFirmware action.

    Published:7 Jun 2018
    7.5
    High

    CVE-2018-12023

    Last Modified: 21 Nov 2024

    An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Oracle JDBC jar in the classpath, and an attacker can provide an LDAP service to access, it is possible to make the service execute a malicious payload.

    Published:8 Jun 2018
    7.5
    High

    CVE-2018-12022

    Last Modified: 21 Nov 2024

    An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Jodd-db jar (for database access for the Jodd framework) in the classpath, and an attacker can provide an LDAP service to access, it is possible to make the service execute a malicious payload.

    Published:29 May 2018
    7.5
    High

    CVE-2018-12018

    Last Modified: 21 Nov 2024

    The GetBlockHeadersMsg handler in the LES protocol implementation in Go Ethereum (aka geth) before 1.8.11 may lead to an access violation because of an integer signedness error for the array index, which allows attackers to launch a Denial of Service attack by sending a packet with a -1 query.Skip value. The vulnerable remote node would be crashed by such an attack immediately, aka the EPoD (Ethereum Packet of Death) issue.

    Published:5 Jul 2018
    7.8
    High

    CVE-2018-11790

    Last Modified: 21 Nov 2024

    When loading a document with Apache Open Office 4.1.5 and earlier with smaller end line termination than the operating system uses, the defect occurs. In this case OpenOffice runs into an Arithmetic Overflow at a string length calculation.

    Published:31 Jan 2019
    9.8
    Critical

    CVE-2018-11788

    Last Modified: 21 Nov 2024

    Apache Karaf provides a features deployer, which allows users to "hot deploy" a features XML by dropping the file directly in the deploy folder. The features XML is parsed by XMLInputFactory class. Apache Karaf XMLInputFactory class doesn't contain any mitigation codes against XXE. This is a potential security risk as an user can inject external XML entities in Apache Karaf version prior to 4.1.7 or 4.2.2. It has been fixed in Apache Karaf 4.1.7 and 4.2.2 releases.

    Published:6 Jan 2019
    4.3
    Medium

    CVE-2018-11784

    Last Modified: 13 Jul 2021

    When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to 7.0.90 returned a redirect to a directory (e.g. redirecting to '/foo/' when the user requested '/foo') a specially crafted URL could be used to cause the redirect to be generated to any URI of the attackers choice.

    Source:Central InfoSec
    Published:3 Oct 2018
    8.1
    High

    CVE-2018-11776

    Last Modified: 27 Aug 2018

    Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by user or a plugin like Convention Plugin) and then: results are used with no namespace and in same time, its upper package have no or wildcard namespace and similar to results, same possibility when using url tag which doesn't have value and action set and in same time, its upper package have no or wildcard namespace.

    Source:Mazin Ahmed
    Published:22 Aug 2018
    5.5
    Medium

    CVE-2018-11771

    Last Modified: 21 Nov 2024

    When reading a specially crafted ZIP archive, the read method of Apache Commons Compress 1.7 to 1.17's ZipArchiveInputStream can fail to return the correct EOF indication after the end of the stream has been reached. When combined with a java.io.InputStreamReader this can lead to an infinite stream, which can be used to mount a denial of service attack against services that use Compress' zip package.

    Published:16 Aug 2018
    4.2
    Medium

    CVE-2018-11770

    Last Modified: 21 Nov 2024

    From version 1.3.0 onward, Apache Spark's standalone master exposes a REST API for job submission, in addition to the submission mechanism used by spark-submit. In standalone, the config property 'spark.authenticate.secret' establishes a shared secret for authenticating requests to submit jobs via spark-submit. However, the REST API does not use this or any other authentication mechanism, and this is not adequately documented. In this case, a user would be able to run a driver program without authenticating, but not launch executors, using the REST API. This REST API is also used by Mesos, when set up to run in cluster mode (i.e., when also running MesosClusterDispatcher), for job submission. Future versions of Spark will improve documentation on these points, and prohibit setting 'spark.authenticate.secret' when running the REST APIs, to make this clear. Future versions will also disable the REST API by default in the standalone master by changing the default value of 'spark.master.rest.enabled' to 'false'.

    Published:13 Aug 2018
    5.9
    Medium

    CVE-2018-11762

    Last Modified: 21 Nov 2024

    In Apache Tika 0.9 to 1.18, in a rare edge case where a user does not specify an extract directory on the commandline (--extract-dir=) and the input file has an embedded file with an absolute path, such as "C:/evil.bat", tika-app would overwrite that file.

    Published:19 Sept 2018
    7.5
    High

    CVE-2018-11761

    Last Modified: 21 Nov 2024

    In Apache Tika 0.1 to 1.18, the XML parsers were not configured to limit entity expansion. They were therefore vulnerable to an entity expansion vulnerability which can lead to a denial of service attack.

    Published:19 Sept 2018
    7.5
    High

    CVE-2018-11759

    Last Modified: 21 Nov 2024

    The Apache Web Server (httpd) specific code that normalised the requested path before matching it to the URI-worker map in Apache Tomcat JK (mod_jk) Connector 1.2.0 to 1.2.44 did not handle some edge cases correctly. If only a sub-set of the URLs supported by Tomcat were exposed via httpd, then it was possible for a specially constructed request to expose application functionality through the reverse proxy that was not intended for clients accessing the application via the reverse proxy. It was also possible in some configurations for a specially constructed request to bypass the access controls configured in httpd. While there is some overlap between this issue and CVE-2018-1323, they are not identical.

    Published:31 Oct 2018
    9.8
    Critical

    CVE-2018-11742

    Last Modified: 4 Dec 2018

    NEC Univerge Sv9100 WebPro 6.00.00 devices have Cleartext Password Storage in the Web UI.

    Source:hyp3rlinx
    Published:26 Dec 2018
    9.8
    Critical

    CVE-2018-11741

    Last Modified: 4 Dec 2018

    NEC Univerge Sv9100 WebPro 6.00.00 devices have Predictable Session IDs that result in Account Information Disclosure via Home.htm?sessionId=#####&GOTO(8) URIs.

    Source:hyp3rlinx
    Published:26 Dec 2018
    9.8
    Critical

    CVE-2018-11736

    Last Modified: 8 Dec 2025

    An issue was discovered in Pluck before 4.7.7-dev2. /data/inc/images.php allows remote attackers to upload and execute arbitrary PHP code by using the image/jpeg content type for a .htaccess file.

    Source:CodeSecLab
    Published:5 Jun 2018
    5.4
    Medium

    CVE-2018-11715

    Last Modified: 5 Jun 2018

    The Recent Threads plugin before 1.1 for MyBB allows XSS via a thread subject.

    Source:0xB9
    Published:4 Jun 2018
    9.8
    Critical

    CVE-2018-11714

    Last Modified: 21 Nov 2024

    An issue was discovered on TP-Link TL-WR840N v5 00000005 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n and TL-WR841N v13 00000013 0.9.1 4.16 v0001.0 Build 170622 Rel.64334n devices. This issue is caused by improper session handling on the /cgi/ folder or a /cgi file. If an attacker sends a header of "Referer: http://192.168.0.1/mainFrame.htm" then no authentication is required for any action.

    Published:4 Jun 2018
    9.8
    Critical

    CVE-2018-11686

    Last Modified: 11 Mar 2019

    The Publish Service in FlexPaper (later renamed FlowPaper) 2.3.6 allows remote code execution via setup.php and change_config.php.

    Source:redtimmysec
    Published:3 Jul 2019
    8.8
    High

    CVE-2018-11671

    Last Modified: 15 Jun 2018

    An issue was discovered in GreenCMS v2.3.0603. There is a CSRF vulnerability that can add an admin account via index.php?m=admin&c=access&a=adduserhandle.

    Source:xichao
    Published:1 Jun 2018
    8.8
    High

    CVE-2018-11670

    Last Modified: 15 Jun 2018

    An issue was discovered in GreenCMS v2.3.0603. There is a CSRF vulnerability that allows attackers to execute arbitrary PHP code via the content parameter to index.php?m=admin&c=media&a=fileconnect.

    Source:xichao
    Published:1 Jun 2018
    9.8
    Critical

    CVE-2018-11652

    Last Modified: 18 Jun 2018

    CSV Injection vulnerability in Nikto 2.1.6 and earlier allows remote attackers to inject arbitrary OS commands via the Server field in an HTTP response header, which is directly injected into a CSV report.

    Source:Adam Greenhill
    Published:1 Jun 2018
    7.5
    High

    CVE-2018-11646

    Last Modified: 12 Jun 2018

    webkitFaviconDatabaseSetIconForPageURL and webkitFaviconDatabaseSetIconURLForPageURL in UIProcess/API/glib/WebKitFaviconDatabase.cpp in WebKit, as used in WebKitGTK+ through 2.21.3, mishandle an unset pageURL, leading to an application crash.

    Source:Dhiraj Mishra
    Published:1 Jun 2018
    4.3
    Medium

    CVE-2018-11631

    Last Modified: 21 Nov 2024

    Rondaful M1 Wristband Smart Band 1 devices allow remote attackers to send an arbitrary number of call or SMS notifications via crafted Bluetooth Low Energy (BLE) traffic.

    Published:31 May 2018
    6.1
    Medium

    CVE-2018-11628

    Last Modified: 5 Jun 2018

    Data input into EMS Master Calendar before 8.0.0.201805210 via URL parameters is not properly sanitized, allowing malicious attackers to send a crafted URL for XSS.

    Source:Chris Barretto
    Published:1 Jun 2018
    9.8
    Critical

    CVE-2018-11586

    Last Modified: 4 Jun 2018

    XML external entity (XXE) vulnerability in api/rest/status in SearchBlox 8.6.7 allows remote unauthenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request.

    Source:Ahmet Gurel
    Published:5 Jun 2018
    4.8
    Medium

    CVE-2018-11581

    Last Modified: 5 Jun 2018

    Cross-site scripting (XSS) vulnerability on Brother HL series printers allows remote attackers to inject arbitrary web script or HTML via the url parameter to etc/loginerror.html.

    Source:Huy Kha
    Published:1 Jun 2018
    4.8
    Medium

    CVE-2018-11564

    Last Modified: 5 Jun 2018

    Stored XSS in YOOtheme Pagekit 1.0.13 and earlier allows a user to upload malicious code via the picture upload feature. A user with elevated privileges could upload a photo to the system in an SVG format. This file will be uploaded to the system and it will not be stripped or filtered. The user can create a link on the website pointing to "/storage/poc.svg" that will point to http://localhost/pagekit/storage/poc.svg. When a user comes along to click that link, it will trigger a XSS attack.

    Source:DEEPIN2
    Published:1 Jun 2018
    8.8
    High

    CVE-2018-11538

    Last Modified: 15 Jun 2018

    servlet/UserServlet in SearchBlox 8.6.6 has CSRF via the u_name, u_passwd1, u_passwd2, role, and X-XSRF-TOKEN POST parameters because of CSRF Token Bypass.

    Source:Ahmet Gurel
    Published:1 Jun 2018
    9.8
    Critical

    CVE-2018-11535

    Last Modified: 29 May 2018

    An issue was discovered in SITEMAKIN SLAC (Site Login and Access Control) v1.0. The parameter "my_item_search" in users.php is exploitable using SQL injection.

    Source:Divya Jain
    Published:29 May 2018
    6.1
    Medium

    CVE-2018-11532

    Last Modified: 29 May 2018

    An issue was discovered in the ChangUonDyU Advanced Statistics plugin 1.0.2 for MyBB. changstats.php has XSS, as demonstrated by a subject field.

    Source:0xB9
    Published:29 May 2018
    8
    High

    CVE-2018-11529

    Last Modified: 18 Oct 2018

    VideoLAN VLC media player 2.2.x is prone to a use after free vulnerability which an attacker can leverage to execute arbitrary code via crafted MKV files. Failed exploit attempts will likely result in denial of service conditions.

    Source:Metasploit
    Published:11 Jul 2018